Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 May 2013You & Me di Borille FabrizoYou & Me di Borille Fabrizo was fined EUR 4,000 by the Italian Garante. The sanction concerned the failure to respond to requests for information about surveillance cameras, which breached data protection rules.ITGaranteGDPR€4,000
15 Dec 2022Scuola Statale Secondaria di I^ grado “Bianco-Pascoli”, di Fasano (BR)The school was fined by the Garante 3,000 EUR for violations in the processing of personal data, including minors' health information. The authority found that the processing lacked a proper legal basis and sufficient transparency.ITGaranteGDPR€3,000
20 Feb 2014Paola ZorzoloPaola Zorzolo was fined for failing to provide adequate privacy information in the video surveillance system at her gaming hall. The authority found a breach of privacy and data protection rules.ITGaranteGDPR€2,400
23 Mar 2017Azienda Sanitaria ULSS 6 di VicenzaAzienda Sanitaria ULSS 6 di Vicenza was fined by the Garante 10,000 EUR for unlawfully communicating an individual's health data to the Comune di Arcugnano without proper authorization. The case involved a breach of lawful processing rules and safeguards for special-category data.ITGaranteGDPR€10,000
17 Oct 2024Serfin 97 S.r.l.Serfin 97 S.r.l. was fined EUR 60,000 by the Garante for unlawful processing of personal data. The company used a third party’s email address to contact a debtor for debt recovery purposes, which breached data protection rules.ITGaranteGDPR€60,000
16 Jan 2026Macelleria La Costata s.r.l.s.The Garante fined Macelleria La Costata s.r.l.s. EUR 1,500 for the non-compliant installation of a video surveillance system. The authority found a breach of GDPR Article 5, which sets out the core principles for personal data processing.ITGaranteGDPR€1,500
26 Mar 2026Ordine degli Avvocati di PiacenzaOrdine degli Avvocati di Piacenza was fined EUR 3,000 by the Garante for improper handling of disciplinary sanctions in its professional register. The authority found that the processing did not comply with data protection requirements.ITGaranteGDPR€3,000
17 Mar 2016Aurelia FevolaAurelia Fevola was fined by the Garante for collecting personal data through her website without providing users with the required information notice. This conduct breached the Italian Data Protection Code.ITGaranteGDPR€2,400
05 Aug 2022Cosmopol Security S.p.A.Cosmopol Security S.p.A. was fined EUR 20,000 by the Garante for failing to respond to a data subject's request to exercise GDPR rights. The case also involved not explaining the origin of the personal data after electronic invoices were received without any contractual relationship.ITGaranteGDPR€20,000
06 Jul 2023SUROVI (Surovi Ristorante indiano e kebab di Chowdhury Monika)The Garante fined SUROVI restaurant EUR 1,000 for operating a video surveillance system without the required privacy notice. The authority found this to be a breach of Article 13 of the GDPR.ITGaranteGDPR€1,000
07 Jul 2022Intesa Sanpaolo Vita S.p.a.Intesa Sanpaolo Vita S.p.a. was fined by the Garante EUR 20,000 for unlawfully disclosing personal data related to a life insurance policy to unauthorized third parties. The breach resulted from an operational error and raised concerns about personal data protection and access controls.ITGaranteGDPR€20,000
01 Jan 2025RaiItaly’s data protection authority fined Rai EUR 150,000 over a Report broadcast on 8 December 2024 that disclosed a private conversation. The case concerns unlawful processing of personal data in a television report.ITGarante per la protezione dei dati personaliGDPR€150,000
04 Dec 2025Istituto Comprensivo di Roverbella (Mantova)Istituto Comprensivo di Roverbella was fined EUR 1,000 by the Garante for breaches of data protection rules. The authority cited non-compliance with the principles of lawfulness, fairness, and transparency in data processing.ITGaranteGDPR€1,000
27 Nov 2025Istituto Comprensivo “G. Falcone” Rende-Quattromiglia (CS)The Garante fined Istituto Comprensivo “G. Falcone” EUR 2,000 for breaches of data processing principles, including lawfulness, fairness, and transparency. The authority also found non-compliance with data processing agreements.ITGaranteGDPR€2,000
16 Jan 2025Comune di CoriThe Garante fined Comune di Cori EUR 2,000 for violations related to the processing of personal data in connection with the issuance of the “Dedicata a te” card. The case involved electronic payment cards provided by Poste Italiane.ITGaranteGDPR€2,000
10 Apr 2025Luka Inc.The Italian data protection authority fined Luka Inc., the US company behind the Replika chatbot, EUR 5,000,000. The 2025-04-10 decision concerned inadequate age verification, an unlawful processing basis, and missing privacy notice information required under the GDPR.ITGarante per la protezione dei dati personaliGDPR€5,000,000
15 Feb 2018APS Holding S.p.a.APS Holding S.p.a. was fined by the Garante 40,000 EUR for failing to properly notify the data processing activities linked to the geolocation of vehicles used in its car sharing service. The authority found that the notification obligations under the Italian data protection code were not met.ITGaranteGDPR€40,000
08 Jun 2023L’Editoriale Nazionale S.r.l.The Garante fined L’Editoriale Nazionale S.r.l. EUR 30,000 for publishing articles that breached privacy rules. The company disclosed personal and sensitive data relating to a deceased minor without showing that the information was essential.ITGaranteGDPR€30,000
12 Jan 2017Centro Studi Raffaello s.r.l.Centro Studi Raffaello s.r.l. was fined by the Garante for inadequate data protection measures and improper collection of consent for marketing purposes. The case indicates deficiencies in the company's personal data processing controls and compliance framework.ITGaranteGDPR€20,000
22 Sept 2011C.T.M. s.p.a.C.T.M. s.p.a. was fined 40,000 EUR by the Italian data protection authority, Garante. The case concerned the failure to formally designate data processors and a breach of minimum security measures required under the Italian Data Protection Code.ITGaranteGDPR€40,000